That Number Looks Familiar — That's Exactly the Point
Your phone lights up. The number looks like it's from your area code — maybe even your own neighborhood prefix. Or it's showing the name of your bank. Or the IRS. Or the Social Security Administration.
You hesitate. It looks legitimate. That hesitation is worth millions of dollars a year to the people calling you.
Caller ID spoofing — the practice of falsifying the number or name that appears on your screen — has become one of the most widely used tools in the modern scammer's playbook. And the uncomfortable truth is that the phone system we all rely on was never designed to prevent it.
How Spoofing Actually Works
To understand why this problem is so stubborn, you need to understand how caller ID was built. The system dates back to the 1980s and was designed with one core assumption: that the entity placing a call would honestly report its own number. There was no authentication layer. No verification handshake. The number you broadcast was simply taken at face value.
Decades later, that architecture is still largely intact — and it's trivially exploitable.
Modern scammers use Voice over Internet Protocol (VoIP) services to place calls over the internet rather than traditional phone lines. Many of these services allow users to manually set the outgoing caller ID to any number they choose. Some platforms were built for legitimate use cases — a business routing calls through a single main number, for example — but the same technology works just as well for fraud.
For less than the cost of a monthly streaming subscription, anyone can access a spoofing service that lets them appear to be calling from a government agency, a Fortune 500 company, or the house next door. No technical expertise required.
The Neighbor Spoofing Playbook
One of the most effective spoofing strategies is so simple it almost feels obvious in hindsight: match the first six digits of your target's phone number.
If your number is 512-743-XXXX, a spoofed call showing up as 512-743-YYYY looks like it's coming from someone in your immediate area — a neighbor, a local business, maybe someone you gave your number to recently. Answer rates for neighbor-spoofed calls are dramatically higher than calls from unknown area codes, which is precisely why scammers default to it.
The strategy works because our instincts around familiarity haven't caught up with the technology. We're still wired to treat a local number as a safer bet.
Who Gets Impersonated Most
Not all spoofing looks the same. Scammers tend to impersonate organizations that carry authority — entities you feel compelled to respond to even if you're skeptical.
Government agencies top the list. The IRS, Social Security Administration, and Medicare are perennial favorites because a call from any of them carries an implied urgency. The threat of back taxes owed or a suspended benefits account is enough to make even savvy people panic.
Financial institutions are a close second. Major banks like Chase, Bank of America, and Wells Fargo are frequently impersonated in fraud schemes designed to capture account credentials or authorize fraudulent transfers. Scammers often pair spoofed bank numbers with a scripted "fraud alert" that pressures you to verify your information immediately.
Healthcare providers and insurance companies have seen a significant spike in impersonation, particularly around Medicare open enrollment periods and following major data breaches that put patient information in circulation.
Tech support scams round out the top tier, with callers spoofing Apple, Microsoft, and major internet service providers to convince targets that their device has been compromised — and that the only fix requires remote access or a prepaid gift card.
The Federal Trade Commission received over 2.6 million fraud reports in 2023, with imposter scams — many initiated by spoofed calls — ranking as the top category by dollar losses.
Why STIR/SHAKEN Isn't the Silver Bullet
The FCC mandated a call authentication framework called STIR/SHAKEN in 2021, requiring major carriers to digitally "sign" calls to verify that the originating number matches the caller's actual identity. It was a meaningful step forward.
But it's not a complete solution — not even close.
First, STIR/SHAKEN only works when both the originating and terminating carriers support it. Smaller carriers, rural networks, and international call routes often fall outside the framework, creating gaps that sophisticated scammers actively exploit.
Second, the system authenticates that a number belongs to the caller — not that the caller is who they claim to be. A scammer using a legitimately registered VoIP number can still pass authentication while pretending to be your bank.
Third, attestation levels vary. A call with "A-level" attestation has been fully verified. "B" and "C" level attestations offer weaker guarantees and are far more common in the wild. Most consumers have no idea these distinctions exist, let alone how to interpret them.
What You Should Do Instead of Trusting the Screen
The mental shift required here is a big one, but it's the only realistic defense: treat caller ID as a starting point for suspicion, not a source of confirmation.
Never call back a number that called you. If someone claims to be from your bank and hangs up, don't redial that number. Find the official customer service number on the back of your card or the bank's website and call that directly. Scammers sometimes set up fake call centers that answer when you call back a spoofed number.
Let unknown calls go to voicemail. Legitimate callers leave messages. Robocalls and scam operations typically don't — or they leave generic, pressure-filled recordings that are easy to identify. Screening through voicemail is one of the most effective low-tech defenses available.
Use call authentication apps that display attestation data. Apps like Hiya, YouMail, and others can surface STIR/SHAKEN attestation levels alongside spam scores, giving you a more complete picture before you decide to engage.
Verify through a second channel. If a caller claims to be from an institution you actually deal with, hang up and contact that institution through a verified method — their app, their official website, or an in-person visit. A legitimate organization will never penalize you for taking an extra step to verify.
Register with the Do Not Call Registry — and understand its limits. The National Do Not Call Registry (donotcall.gov) reduces legitimate telemarketing calls but has zero effect on scammers, who are already operating outside the law. It's a useful filter, not a complete shield.
The Bigger Problem With "Verified" Calls
Here's the uncomfortable irony: as call authentication technology improves and more calls display a "Verified" badge on your screen, scammers will adapt. They already are. Some fraud operations now acquire legitimate phone numbers specifically to pass authentication checks, then use those numbers in short bursts before rotating to new ones.
The "Verified" label is becoming the new trust signal to exploit — because the moment consumers learn to trust it, it becomes the most valuable thing to fake.
The most reliable protection isn't any single technology. It's a habit of healthy skepticism toward any unsolicited call, regardless of what name or number shows up on your screen.
Because the most dangerous call you'll receive this year probably won't look dangerous at all.